FirmProof
Draft. Pending formation completion. Fields marked “to be published on completion” will be filled in once FirmProof, Inc. is filed and the EIN is issued. Every other claim on this page is currently true.

Our trust principles

These are commitments, not aspirations. They govern how we build product and how we handle customer data.

  1. Source-grounded outputs. Every FirmProof recommendation, evidence assessment, or advisory output traces to specific, checkable support. If it does not cite, it does not ship.
  2. Uncertainty exposed. Recommendations show confidence and known unknowns. We do not present model output as settled fact.
  3. Human approval preserved. No FirmProof output moves from draft to approved without a named human decision. We log the approver, the moment, and the underlying evidence.
  4. No cross-customer training on customer content without explicit written agreement. Customer data isolation is a hard boundary.
  5. Reversible AI actions only. If an AI-suggested action cannot be undone by a person within 15 minutes, it goes through an approval gate.
  6. Data minimization by default. We collect the smallest set of customer data that lets the workflow function. We delete on a documented cadence.

Where we are today

FirmProof is an early-stage company. We are transparent about that because a prospect deserves to know what an engagement with us actually looks like at this stage.

What we have in place:

  • Password manager and multi-factor authentication on every business account
  • Full-disk encryption on all company machines
  • Distinct browser profile isolating company work from personal accounts
  • GitHub organization-level 2FA requirement, branch protection on production repositories, secret scanning, and Dependabot enabled
  • Data inventory maintained internally
  • Sub-processor list published (below)
  • Written retention rules for each data category
  • AI provider register with data-handling terms verified for each provider
  • Incident response plan (written; not yet exercised in a tabletop)

In progress or planned (with our commitment to build):

  • Delaware C-corporation formation. Not yet filed. The filing date and EIN will be published here once complete.
  • Cyber insurance policy. To be procured before the first paid pilot.
  • SOC 2 Type I audit. Planned at completion of the first paid pilot cohort.
  • SOC 2 Type II audit. 12 months after Type I completion.
  • Independent penetration test. Planned before general availability.
  • Formal vendor risk management program. To be formalized when we cross a defined threshold of active engagements.

If a required standard is not on this list and you need it, tell us. We will either commit to a timeline or tell you we are not the right partner today.

How we handle your data

Data we collect from you

  • During prospecting and evaluation: contact information, company information, and any documents or sample data you choose to share with us.
  • During an active engagement: whatever the specific engagement requires. We work with you at kickoff to define the minimum data set and document it in writing.
  • From your use of our software (once in production): system telemetry (feature usage, error logs, session duration) for the purpose of improving the product and diagnosing issues. This is standard product analytics; we do not sell or transfer it outside our sub-processor list.

Data isolation

Each customer's data is logically isolated at the tenant level within our systems. Customer-uploaded artifacts, evidence, and configurations are not accessible to other customers. This includes access by our own team: only named FirmProof personnel with a documented need for a specific engagement have access to that engagement's data, and access is logged.

AI providers and model training

FirmProof uses commercial AI model providers (currently: OpenAI, Anthropic, Perplexity) in specific workflows. For every provider we use to process customer data:

  • We route customer data through the provider's zero-retention or opt-out-of-training endpoint or configuration.
  • We have documentary evidence of that setting for each provider, available on request under NDA.
  • We do not fine-tune models on customer content without explicit written agreement.
  • If a provider changes their data-handling terms, we update this page within 30 days and notify affected customers.

Retention

  • Prospect communications: retained for up to 24 months, then deleted, unless the prospect becomes a customer.
  • Design partner and pilot artifacts: retained for the duration of the engagement plus 30 days, then deleted or returned per the engagement agreement.
  • Session recordings from demos: retained for 90 days by default. Longer retention requires the participant's written consent.
  • Production customer data (once we have it): retained per the terms of the customer's Master Service Agreement and Data Processing Addendum. Default: duration of the engagement plus 30 days for deletion, or return on request.

Deletion

Customer data is deleted within 30 days of a written deletion request, or at the end of the retention period, whichever comes first. Backups containing customer data are purged on the next backup rotation cycle, which is a maximum of 90 days.

Sub-processors

The following third parties may process customer data in the course of our operations. We update this list within 30 days of any change. Adding a new sub-processor that will process customer data requires notice to affected customers.

| Sub-processor | Purpose | Data types | | ------------------------- | -------------------------------------------------- | ----------------------------------------------------------- | | Proton AG | Business email and calendar | Email content, contact information | | Porkbun | Domain registration | Domain configuration only, no customer content | | Google (Workspace, Drive) | Document storage and collaboration | Documents and artifacts we choose to store there | | GitHub | Source code and internal knowledge storage | Source code, internal documentation | | Attio | Customer relationship management | Contact and engagement metadata | | Cal.com | Meeting scheduling | Calendar invitations and meeting metadata | | Vercel | Website hosting for firmproof.io | Site request logs, no customer product data | | PostHog | Product analytics (cookieless) | Aggregate page-view telemetry, no customer-uploaded content | | OpenAI | AI model provider for specific reasoning workflows | Content processed through zero-retention endpoints only | | Anthropic | AI model provider for specific reasoning workflows | Content processed through zero-retention endpoints only | | Perplexity | AI research and reasoning workflows | Content processed through zero-retention endpoints only |

Security controls

Access control

  • Multi-factor authentication required on every FirmProof account. Hardware security key (YubiKey) or authenticator app (TOTP) preferred over SMS.
  • Password manager (Proton Pass) for every credential. No shared or reused passwords.
  • Access to customer data restricted to named personnel with a documented need for a specific engagement. Access is logged.
  • Immediate access revocation on departure.

Device security

  • Full-disk encryption enabled on all company devices.
  • Automatic operating system and browser security updates enabled.
  • Distinct browser profiles for company work.
  • Company work does not occur on personal devices or devices shared with non-FirmProof personnel.

Code and infrastructure

  • Source code in private GitHub repositories under the FirmProof organization.
  • Organization-level 2FA required.
  • Branch protection on production branches, requiring code review before merge (once we have more than one engineer).
  • Secret scanning enabled on all repositories. No credentials committed to source control.
  • Dependency vulnerability scanning (Dependabot) enabled and monitored.

Backups

  • Local device backups: encrypted external storage.
  • Cloud service backups: retained per each provider's default (Proton, GitHub, Attio, Google Drive).
  • Recovery is tested monthly on rotation.

Monitoring

  • Access logs reviewed weekly.
  • Security-relevant provider alerts (GitHub security advisories, unauthorized login attempts) monitored in real time.
  • Incident response plan documented and reviewed quarterly.

Incidents

How we define an incident

An incident is any event that (a) causes unauthorized access to customer data, (b) causes unauthorized modification or deletion of customer data, or (c) causes an interruption of service to customers exceeding four hours.

How we respond

  1. Contain. Isolate the affected system or account within one hour of detection.
  2. Assess. Determine what data or systems are affected within 24 hours.
  3. Notify affected customers within 72 hours of confirmation, with what we know and what we are still investigating.
  4. Remediate. Fix the root cause. Provide a written post-incident report within 14 days.

History

No security incidents to date.

Governance and AI use

FirmProof uses AI models as a core part of the product. That warrants specific transparency.

Which models we use and why. We use commercial large language models from OpenAI, Anthropic, and Perplexity for specific workflows: evidence assessment, policy currency analysis, control-mapping suggestions, and drafting. We use each provider for the workflow where their model performs best in our evaluation. We do not use open-source or self-hosted models today. If that changes, this page will reflect it.

What data goes to models. Only the data required for the specific workflow, routed through the provider's zero-retention or training-opt-out configuration. Customer artifacts are not used to train foundation models under any circumstance without explicit written customer agreement.

How we handle model errors. Every model output is presented with confidence indicators and the underlying evidence citations. A named human, either a FirmProof employee, a customer employee, or both, must approve any output before it moves from draft to settled. We log the approval.

EU AI Act positioning. FirmProof's product is not intended to be a "high-risk AI system" under Annex III of the EU AI Act. We do not use AI to make decisions about employment, credit, education, essential public services, law enforcement, migration, or judicial administration. Our AI outputs are advisory and require human approval before action. If a customer intends to use FirmProof in a way that would place the AI component in the high-risk category under their applicable regulation, that use is out of scope of our current product and requires a written agreement addressing the additional obligations.

Data protection compliance.

  • We follow GDPR principles for any EU personal data we process.
  • We follow CCPA/CPRA principles for any California personal data we process.
  • We execute the customer's Data Processing Addendum on request or provide our own template. Contact us for current DPA terms.

Legal and corporate

  • Legal entity: Not yet incorporated. FirmProof is operated by its founder, Robert Hudson, until FirmProof, Inc. is formed as a Delaware C-corporation.
  • Formation date: to be published on completion.
  • Principal place of business: Austin, Texas, USA.
  • EIN: to be published on completion.
  • Registered agent: to be published on completion.
  • Insurance: Cyber liability insurance will be in force before the first paid pilot; coverage details available on request under NDA once bound.

How to raise a concern

  • Security concern about FirmProof itself (suspected vulnerability, incident, policy question): security@firmproof.io. Response within one business day.
  • Privacy or data-handling question: privacy@firmproof.io. Response within three business days.
  • General inquiry: founder@firmproof.io. Response within three business days.

We support responsible security disclosure. If you believe you have found a vulnerability in FirmProof's systems, please email security@firmproof.io with the details. We will acknowledge within one business day, keep you informed of our remediation, and credit you publicly if you wish.


This page is maintained by the FirmProof team. Every 90 days it is reviewed against current practice and updated. If a claim on this page is inaccurate at the time you read it, please tell us at founder@firmproof.io.